Examples of HPsus/VBCheM-B include:
Example 1
File Information
- Size
- 96K
- SHA-1
- 4eee4aff58bc59e3e87200fe414c8eca6beffcca
- MD5
- c051d9388c50591eef7203b7ac98a06d
- CRC-32
- 8c0e6bd4
- File type
- Windows executable
- First seen
- 2012-05-05
Runtime Analysis
Dropped Files
- c:\Documents and Settings\test user\yiiagu.exe
- Size
- 96K
- SHA-1
- cd87e3ee37c656ad03dbd8dc5a081bf5ede2c0ca
- MD5
- 0be6865afc34db1238998649a225de76
- CRC-32
- 6d643281
- File type
- Windows executable
- First seen
- 2012-05-16
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- yiiagu
- c:\Documents and Settings\test user\yiiagu.exe /l
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
- NoAutoUpdate
- 0x00000001
Registry Keys Modified
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
- ShowSuperHidden
- 0x00000000
DNS Requests
Example 2
File Information
- Size
- 121K
- SHA-1
- 9427d267ce71e52557959c45bd51eafffddbe54d
- MD5
- 4e90007f712bcc814f1cfc9ed6c5205b
- CRC-32
- 58bf626d
- File type
- Windows executable
- First seen
- 2007-05-06
Runtime Analysis
Dropped Files
- C:\TUAutoUpdLog.log
- Size
- 113
- SHA-1
- 831455f5e47528f383782ccbf334e9f2217199ee
- MD5
- fedbaad97215685012502ada21c7dfc8
- CRC-32
- 1fb4a095
- File type
- Data Log File (generic)
- First seen
- 2012-06-24
- C:\LastTUUpdate.ini
- Size
- 49
- SHA-1
- a37b661bd60b29abdadd3b8e5e11338e84ad5b95
- MD5
- cd08c60cd41fa872feadfa88fcb1b9a4
- CRC-32
- 72684db4
- File type
- Configuration Data File (generic)
- First seen
- 2012-06-24
Example 3
File Information
- File type
- Windows executable